The SEC imposed a $575,000 penalty on OTC Link LLC in September 2026 for violations spanning August 2016 to March 2025. The enforcement action focused on the firm's failure to establish, maintain, and enforce policies required under Regulation SCI for its alternative trading system. What makes this case instructive isn't the penalty amount, it's the pattern. SEC Division of Examinations staff flagged the same deficiencies across multiple examination cycles. OTC Link LLC left required policies in draft form, failed to finalize them, and didn't enforce what did exist. The firm's response to repeated regulatory findings was, effectively, no response at all.
This case demonstrates what happens when examination findings become background noise rather than action items.
What the Enforcement Order Reveals
Policy Gaps Persisted Across Core SCI Requirements
OTC Link LLC lacked written policies reasonably designed to ensure adequate capacity, integrity, resiliency, availability, and security for its SCI systems, violating Rule 1001(a)(1). The deficiencies weren't limited to one control area. The firm failed to establish policies for system security, access control, and application vulnerability management, testing, and remediation. These aren't niche requirements, they're foundational to Regulation SCI's framework for maintaining operational capability and fair and orderly markets.
Examination Findings Were Flagged Multiple Times
Division of Examinations staff examined OTC Link ATS several times during the violation period. Each examination identified policies that remained in draft form or didn't exist. Each examination gave the firm an opportunity to remediate. The firm didn't act. This pattern of inaction across examination cycles led the SEC to characterize the behavior as "disregard for their findings and the overall examinations process."
Violations Extended to Review and Remediation Obligations
Beyond the missing policies, OTC Link LLC violated Rules 1001(a)(2) and 1001(a)(3) by failing to periodically review the effectiveness of its policies and procedures and failing to take prompt action to remedy deficiencies. These provisions require SCI entities to maintain an active compliance posture, not just document policies once and file them away.
What This Means for Your Audit Program
If you're an internal auditor at an SCI entity or any organization subject to recurring regulatory examinations, this case clarifies where your program must focus.
Examination findings are not advisory observations. When a regulator flags a deficiency during an examination, your organization has entered a documented remediation timeline. The finding goes into the regulator's records. If the same deficiency appears in the next examination cycle, you're building evidence of a pattern. By the third cycle, you're demonstrating disregard.
Draft policies don't satisfy regulatory obligations. A policy in draft form, no matter how detailed, doesn't meet the "establish, maintain, and enforce" standard. If your compliance team has been working on a security policy for eighteen months and it's still in draft, you don't have a security policy. You have a compliance gap with documentation of your awareness of that gap.
Periodic review requirements demand scheduled action. Rule 1001(a)(2) requires periodic review of policy effectiveness. This isn't an invitation to review when convenient. You need a documented review schedule, evidence of reviews conducted on that schedule, and records showing what changed as a result. If your last policy review was "sometime in 2023," you're not meeting the standard.
Action Items by Priority
Immediate (Next 30 Days)
Map all open examination findings to remediation owners and deadlines. Pull every examination report from the past three years. Identify findings that remain open or were only partially addressed. Assign a named owner and a completion date to each item. If you discover findings that were never formally closed out, escalate immediately.
Audit the status of draft policies referenced in past examinations. Search your document management system for policies marked as draft, particularly those related to system security, access control, and vulnerability management. If a draft policy has existed for more than 90 days, either finalize it or document why it hasn't been finalized and what the interim control is.
Verify your periodic review schedule exists and is current. Confirm you have a documented schedule for reviewing the effectiveness of all SCI-related policies. Check whether reviews occurred as scheduled in the past twelve months. If reviews were skipped or delayed, document the gap and schedule catch-up reviews.
Short-Term (Next 90 Days)
Establish a formal examination response protocol. Document how your organization will respond to examination findings. The protocol should specify who receives findings, who assigns remediation tasks, what documentation is required to close a finding, and how you'll verify closure before the next examination cycle. This protocol should be approved by senior management and reviewed by legal counsel.
Conduct a gap analysis against Rule 1001(a)(1) requirements. Review your current policies for capacity, integrity, resiliency, availability, and security. Compare them to the specific requirements in Rule 1001(a)(1). Document any areas where policies are missing, incomplete, or not enforced. Prioritize gaps that align with areas flagged in past examinations.
Implement a finding-tracking system with escalation triggers. If an examination finding remains open past its target remediation date, the system should automatically escalate to the chief compliance officer. If a finding remains open for two examination cycles, it should escalate to the audit committee. This prevents findings from becoming invisible.
Long-Term (Next 12 Months)
Build examination readiness into your annual audit plan. Schedule internal audits of SCI policy areas in the quarter before you expect regulatory examinations. This gives you time to identify and fix issues before examiners arrive. Focus your pre-examination audits on areas that were flagged in previous cycles.
Develop metrics for remediation velocity. Track the average time from examination finding to verified closure. If this metric is increasing, your remediation process is degrading. Report this metric to the audit committee quarterly alongside the count of open findings by age.





